[Solved] Tls-crypt authentication not supported on certain vpn providers

10 Posts
4 Users
2 Reactions
54 Views
(@st-ryoh)
Active Member
Joined: 1 Jahr ago
Posts: 4
Topic starter  

*edit*

Actually it looks like it is supposed to be officially supported

https://eblocker.org/en/docs/where-can-i-find-the-required-openvpn-files-for-the-eblocker/

........

I want to preface this by saying, I realize protonvpn is not an officially supported provider. That said, I can only reproduce this issue using protonvpn.

Screenshot 20240102 120249 Chrome

 

Basically,  protonvpn does not support tls-auth based authentication. They use tls-crypt with a static key. Which prevents it from authenticating in eblocker. Additionally, I don't see an option to use tls-crypt in eblocker. In fact, when loading the ovpn config for proton, I see that tls-crypt listed as an "ignored setting". 

Now, if there are no plans to support tls-crypt currently or in the future, I do have to suggest one correction to the ip-anonimization setup wizard: that tls-crypt be moved to "unsupported" instead of "ignored". Because it does break the ability to connect.

Client OS
Browser
eBlocker hardware
eBlockerOS version

   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 5 Jahren ago
Posts: 2020
 

@st-ryoh Thanks very much for your feedback. I guess the config parser as well as the OPVN client need to be updated to support VPN providers using tls-crypt.

If you are a developer you are highly invited to join and help updating the component.

THX!


   
ReplyQuote
(@st-ryoh)
Active Member
Joined: 1 Jahr ago
Posts: 4
Topic starter  

@random ,

Thanks for your reply.

I'll check for a contribution guide and see I if can help.


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 5 Jahren ago
Posts: 2020
 

@st-ryoh Sounds great!

I've talked to @bpr (Boris) the project maintainer. He told me the openvpn client already supports tls-crypt. So it's probably just the config parser that needs to be updated.

@bpr Could you point @st-ryoh into the right direction?

THX!


   
ReplyQuote
(@bpr)
Famed Member Admin
Joined: 5 Jahren ago
Posts: 287
 

@st-ryoh, @random,

Thank you for the hint. The fix was simple, the tls-crypt option was just not in the whitelist of known options yet. I added an issue on GitHub: https://github.com/eblocker/eblocker/issues/323

I tested the fix successfully with Proton VPN Free.

It will be fixed in 3.0.2 which is coming soon.


   
Random reacted
ReplyQuote
(@st-ryoh)
Active Member
Joined: 1 Jahr ago
Posts: 4
Topic starter  

@bpr , @random 

Sounds like the dev work is already completed. 

Is there anything else I can help with or should I marked this as resolved? 

 

Thanks


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 5 Jahren ago
Posts: 2020
 

@st-ryoh I'll gladly mark the thread as "solved" once we've released the fix and everyone is happy. Of course you can mark the thread fixed too if tls-crypt works for you then.

If you feel like contributing to the project in other means you are very welcome to join. Just drop an email to volutary at eBlocker.org and @benne or @bpr will surely take care of you. 😉👍

THX!

 


   
ReplyQuote
(@random)
Illustrious Member Admin
Joined: 5 Jahren ago
Posts: 2020
 

@st-ryoh Yesterday we've released eBlockerOS 3.0.2 supporting TLS crypt. Proton and other VPN providers using this option should now work properly again.

A brief confirmation from your side would be great 👍

If you feel like contributing to the project I'd like to kindly invite you again to drop an email to voluntary at eBlocker.org and we'll set you up... 🚀 

THX!


   
ReplyQuote
(@bastet)
Eminent Member
Joined: 4 Jahren ago
Posts: 14
 

Protonvpn provides free serverfiles.ovpn for Japan, the Netherlands and the USA. In the eBlocker you do NOT need to enter the login data that you have created for "normal" access to "protonvpn.com". Protonvpn provides its own combination of username and password, free for this purpose: This can be accessed via "https://account.protonvpn.com/account", log in there with the "normal" login data mentioned above and use the access combination found under "OpenVPN / IKEv2 username" in the eBlocker (anonymisation).
Best regards


   
Random reacted
ReplyQuote
(@st-ryoh)
Active Member
Joined: 1 Jahr ago
Posts: 4
Topic starter  

@random I can confirm This is now working with ProtonVPN premium for me. I also sent an email to the address you listed above. 


   
ReplyQuote

Nach oben scrollen